Critical flaw in Microsoft Exchange: hackers can read others' mailboxes
Microsoft issued an urgent update for Exchange Server, fixing a serious vulnerability CVE-2026-96940 rated 8.8/10. The flaw allows an authenticated attacker to escalate privileges and access mailboxes of other employees in the same organization. Though no active attacks have been reported, Microsoft rated the vulnerability as "more likely to be exploited" and recommends immediate installation of the patch.
Full text
Microsoft issues fix for CVE-2026-96940, a high-severity Exchange privilege-escalation flaw
Attackers with compromised user credentials could access other employees’ mailboxes and emails
No active exploitation reported, but Microsoft labeled the vulnerability “exploitation more likely"
Microsoft has pushed an urgent update for Exchange Server which fixes a high-severity flaw that could wreak some serious havoc among email users.
The company patched CVE-2026-96940, a “weak authorization in Microsoft Exchange Server [that] allows an authenticated attacker to elevate privileges over a network,” as per the National Vulnerability Database (NVD).
According to Microsoft’s advisory the bug, which was given a severity rating of 8.8/10 (high), can be abused to gain unauthorized access to people’s inboxes within the same organization.
In theory, threat actors who obtained credentials of a low-privileged Exchange user could exploit CVE-2026-96940 to escalate their privileges within Exchange, and then read confidential emails and attachments belonging to other people working for the same organization.
The bug cannot be exploited for cross-tenant access, though.
Establishing a foothold
To exploit the vulnerability, the threat actor needs to have authenticated access beforehand. This, however, is not a major obstacle for the attackers, since they can easily purchase login credentials from the dark web, or use phishing to deploy an infostealer capable of extracting these secrets.
Therefore, even an email account of an “ordinary” employee can be enough to establish a foothold, escalate privileges, and access inboxes belonging to higher echelons within an organization.
At that point, the vulnerability becomes highly valuable. Corporate email accounts can contain confidential documents, contracts, invoices, internal discussions, and other sensitive information, which the attackers can then use for follow-up attacks such as Business Email Compromise (BEC).
It is worth stressing that CVE-2026-96940 is not known to grant administrator or SYSTEM-level privileges on the underlying Windows server. Instead, Microsoft’s disclosed attack scenario focuses on escalating privileges within Exchange and gaining unauthorized access to other users’ mailboxes
Users of Exchange Online are already secured, Microsoft further explained, since it deployed a related “service-side” fix. However, those using on-prem Microsoft Exchange Server products should upgrade to the latest version to avoid being targeted.
Here is a list of the affected versions:
- Microsoft Exchange Server Subscription Edition RTM
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Exchange Server 2019 Cumulative Update 14
Microsoft says there is no evidence of the flaw being abused in the wild, and at press time, the US Cybersecurity and Infrastructure Security Agency (CISA) does not have it listed in its Known Exploited Vulnerabilities (KEV) catalog. However, the Windows maker labeled the bug as “exploitation more likely” suggesting that cybercriminals might try to exploit it, and warning users to apply the provided fix as soon as possible.
It is also worth mentioning that both Exchange Server 2016 and Exchange Server 2019 reached their end of support last year. Microsoft said that these latest security updates are only available to organizations enrolled in its Period 2 Extended Security Update (ESU) program.
The program gives eligible Exchange Server 2016 and 2019 customers access to security updates released between May and the end of October 2026. Organizations that have not enrolled are being urged to migrate to Exchange Server Subscription Edition (SE) if they want to continue receiving the latest security fixes.
Unusual release
Microsoft issued the patch on October 2, as part of its September 2026 V2 Exchange Server Security Updates. The original September updates were pushed on September 8, and the software giant added that the main difference between these two versions is the fix for CVE-2026-96940.
As it was releasing the patch, it confirmed it was pushing it “ ahead of its intended schedule ”, without elaborating further. Perhaps labeling it as “exploitation more likely” is elaborating enough, especially since the company urged customers to review its deployment guidance and apply the update as soon as possible.
fter installing the update, administrators are also advised to run Microsoft’s Exchange Server Health Checker. The tool can verify whether the security update was installed successfully and determine whether any additional action is required.
Via The Hacker News
Similar stories
💻 Technology
Nearly 40,000 phishing attacks on US financial firms in first half of year
TechRadar · 23h ago
💻 Technology
Russian hacker group Star Blizzard intensifies phishing attacks since early 2026
CyberDefence24 · 4d ago
🚨 Crime
Lower Silesian Police warn of fake message impersonating authorities
Policja.pl · 7d ago
Similar stories
💻 Technology
Nearly 40,000 phishing attacks on US financial firms in first half of year
TechRadar · 23h ago
💻 Technology
Russian hacker group Star Blizzard intensifies phishing attacks since early 2026
CyberDefence24 · 4d ago
🚨 Crime
Lower Silesian Police warn of fake message impersonating authorities
Policja.pl · 7d ago
Should companies be legally required to patch critical vulnerabilities immediately?
Comments
No comments yet
Comments
No comments yet — be the first to weigh in 👇
No comments yet. Be the first!